Skip to content

Commit b06a4e5

Browse files
committed
Merge remote-tracking branch 'origin/master' into release51
2 parents 3ef299f + 8a3e60c commit b06a4e5

File tree

6 files changed

+22
-3
lines changed

6 files changed

+22
-3
lines changed

.github/workflows/node.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -240,6 +240,8 @@ jobs:
240240
- name: Trivy scanning
241241
if: steps.check-build-and-push.outputs.enable == 'true' && steps.check-ghcr.outputs.enable == 'true' && steps.ghcr-tag.outputs.tags != 0
242242
uses: aquasecurity/[email protected]
243+
env:
244+
TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db
243245
with:
244246
image-ref: "${{ steps.trivy-image.outputs.image }}"
245247
format: "table"
@@ -389,6 +391,8 @@ jobs:
389391
- name: Trivy scanning
390392
if: steps.check-build-and-push.outputs.enable == 'true' && steps.check-ghcr.outputs.enable == 'true' && steps.ghcr-tag.outputs.tags != 0
391393
uses: aquasecurity/[email protected]
394+
env:
395+
TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db
392396
with:
393397
image-ref: "${{ steps.trivy-image.outputs.image }}"
394398
format: "table"

.github/workflows/prune-container-images.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,8 @@ on:
77

88
jobs:
99
prune-container-images:
10+
if: ${{ github.repository_owner == 'nrkno' }}
11+
1012
uses: nrkno/sofie-github-workflows/.github/workflows/prune-container-images.yml@main
1113
strategy:
1214
max-parallel: 1

.github/workflows/prune-tags.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,8 @@ on:
1616

1717
jobs:
1818
prune-tags:
19+
if: ${{ github.repository_owner == 'nrkno' }}
20+
1921
name: Prune tags
2022
runs-on: ubuntu-latest
2123
timeout-minutes: 15

.github/workflows/trivy.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@ on:
66

77
jobs:
88
trivy:
9+
if: ${{ github.repository_owner == 'nrkno' }}
10+
911
name: Trivy scan
1012
runs-on: ubuntu-latest
1113
strategy:
@@ -16,13 +18,17 @@ jobs:
1618
steps:
1719
- name: Run Trivy vulnerability scanner (json)
1820
uses: aquasecurity/[email protected]
21+
env:
22+
TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db
1923
with:
2024
image-ref: ghcr.io/nrkno/sofie-core-${{ matrix.image }}:latest
2125
format: json
2226
output: '${{ matrix.image }}-trivy-scan-results.json'
2327

2428
- name: Run Trivy vulnerability scanner (table)
2529
uses: aquasecurity/[email protected]
30+
env:
31+
TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db
2632
with:
2733
image-ref: ghcr.io/nrkno/sofie-core-${{ matrix.image }}:latest
2834
output: '${{ matrix.image }}-trivy-scan-results.txt'
@@ -39,6 +45,8 @@ jobs:
3945
4046
- name: Run Trivy in GitHub SBOM mode and submit results to Dependency Graph
4147
uses: aquasecurity/[email protected]
48+
env:
49+
TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db
4250
with:
4351
format: 'github'
4452
output: 'dependency-results-${{ matrix.image }}.sbom.json'

CONTRIBUTING.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,4 +9,5 @@ This repository uses the following branches:
99
* **_master_** is our main branch. We consider it stable and it is used in production.
1010
* The **_releaseXX_** branches are our in-development branches. When a release is ready, we decide to “freeze” that branch and create a new **_releaseXX+1_** branch.
1111

12-
We encourage you to base your contributions on the latest **_releaseXX_** branch, alternatively the **_master_** branch or a recently frozen **_releaseXX_** branch. The [_Sofie Releases_](https://nrkno.github.io/sofie-core/releases) page collects the status and timeline of the releases.
12+
We require contributions to be based based on the latest **_release\*_** branch.
13+
The [_Sofie Releases_](https://nrkno.github.io/sofie-core/releases) page collects the status and timeline of the releases.

packages/documentation/docs/for-developers/contribution-guidelines.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,8 @@ sidebar_position: 2
77

88
# Contribution Guidelines
99

10+
_Last updated september 2024_
11+
1012
## About the Sofie TV Studio Automation Project
1113

1214
The Sofie project includes a number of open source applications and libraries developed and maintained by the Norwegian public service broadcaster, [NRK](https://www.nrk.no/about/). Sofie has been used to produce live shows at NRK since September 2018.
@@ -35,8 +37,8 @@ However, Sofie is a big project with many differing users and use cases. **Large
3537
3. (If needed) NRK establishes contact with the RFC author, who will be invited to a workshop where the RFC is discussed. Meeting notes are published publicly on the RFC thread.
3638
4. The contributor references the RFC when a pull request is ready.
3739

38-
### Base contributions on the in-development branch (or the master branch)
39-
In order to facilitate merging, we ask that contributions are based on the latest (at the time of the pull request) _in-development_ branch (often named `release*`), alternatively the stable (eg. `master`) branch. NRK will take responsibility for rebasing stable contributions to the latest in-development branch if needed.
40+
### Base contributions on the in-development branch
41+
In order to facilitate merging, we ask that contributions are based on the latest (at the time of the pull request) _in-development_ branch (often named `release*`).
4042
See **CONTRIBUTING.md** in each official repository for details on which branch to use as a base for contributions.
4143

4244
## Developer Guidelines

0 commit comments

Comments
 (0)